CISCO Security Advisory

Published Date: July 20, 2026

CVE: CVE-2025-20204

Advisory Summary

Cisco has disclosed multiple stored Cross-Site Scripting (XSS) vulnerabilities within the web-based management interface of their Identity Services Engine (ISE) guest portals. These weaknesses arise from inadequate user input validation, enabling authenticated attackers with administrative credentials to inject malicious scripts into specific interface pages.

Successful exploitation could allow attackers to run arbitrary script code in the context of the affected interface or obtain sensitive browser-based information, posing a significant risk to session integrity and user data confidentiality.

Actionable Recommendation: IT security teams managing Cisco ISE deployments should prioritize deploying the provided software patches immediately to mitigate potential XSS exploitation risks. Regularly reviewing user privileges and monitoring administrative access logs remain essential preventive measures.

🔗

Reference: Vendor Advisory